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The text of all pending claims is set forth below. The claims as listed below show added 
text with underlininq and deleted text with i^itethreugk The status of each claim is indicated 
with one of (original), (currently amended), (cancelled), (withdrawn), (new), (previously 
presented), or (not entered). 

Please ADD new claims 9 and 1 0 and AMEND the claims in accordance with the 
following: 



1 . (CURRENTLY AMENDED) A security system comprising an information 
management system for monagingthat manages information and an encryption support system 
fe^pportm g t hat supports encryption of information in the Information management system. 

the encryption support system including 

an encryption rule storing portion fer-stofi mthat stores rule information that indicates an 
encryption rule of the information for each secret level that is a level of wanting to keep 
information secret, 

an encryption data transmitting portion for tronomltttng that transmj ts encryption data that 
is necessary for encrypting Information in accordance with the rule to the information 
management system, 

a process information receiving portion for rooc i ving t hat receives process information 
that indicates the encryption process performed by the information management system from 
the information management system, 

a monitoring portion f&FfBontterin gthat monitors whether or not the encryption of 
information is performed in accordance with the rule by the information management system on 
the basis of the process information received from the information management system, and 

a warning portion for warninothat warns the information management system that was 
found to encrypt information not in accordance with the rule by the monitoring portion to do 
encryption of information in accordance with the rule, and 

the information management system including 

an encryption data receiving portion for rocoiv i ng that receives the encryption data from 
the encryption support system, 

a classification secret level storing portion fe^atofin ethat stores classification of 
information managed by the information management system in connection with the secret level 
for each of the classification, 
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an encrypting portion for onorvptinqthat encryp ts information managed by the information 
management system by using the encryption data of the secret level corresponding to the 
classification of the information received by the encryption data receiving portion, 

an information storing portion ferete4n athat stores the information encrypted by the 
encrypting portion, and 

a process information transmitting portion for tranom i tting that transmits the process 
information about the encryption performed by the encrypting portion to the encryption support 
system. 

2. (ORIGINAL) The security system according to claim 1, wherein the rule 

information indicates the rule including an encryption system that Is used for encryption and a 

valid term of an encryption key that is used for the encryption, 

if a period since the information management system encrypted information until the 

present time exceeds the valid term relevant to the rule of the secret level corresponding to the 

classification of the information, 

the warning portion warns the information management system, 

if the encryption system that is indicated in the rule information is changed, 

the encryption data transmitting portion transmits the encryption data for performing 

encryption with the changed encryption system to the information management system, and 
the warning portion warns to perform encryption of information in accordance with the 

changed encryption system. 

3. (CURRENTLY AMENDED) The security system according to claim 1, wherein the 
information management system includes 

a classification secret level transmitting portion feMraftsmittif Ktthat transmits classification 
secret level information that indicates classification of information managed by the information 
management system and the secret level corresponding to the classification to the encryption 
support system, and 

the monitoring portion performs the monitoring by comparing the process information 
received from the information management system with the classification secret level 
information. 



PAGE 4113 * RCVD AT 711212007 10:00:15 PM [Eastern Daylight Time] * SVR:USPT0-EFXRF-1/12 * DNIS:2738300 1 CSID: * DURATION (mm-ss):03-54 



JUL. 12.' 2007 1 0:01 PM STAAS & HALSEY -202-434-1501 NO. 4734 P. 5/13 



Serial No. 10/763.275 

4. (CURRENTLY AMENDED) The security system according to claim 1 , further 
comprising a valid term managing portion feHttaoaging that manages a valid term of a 
certification for affixing an electronic signature to information, wherein 

the monitoring portion monitors whether or not it is necessary to reaffix the electronic 
signature to the information in accordance with the valid term of the certification, and 

the warning portion warns the information management system for managing the 
information to reaffix the electronic signature if it is decided that it is necessary to reaffix the 
electronic signature. 

5. (CURRENTLY AMENDED) An information management system for 
managjngt hatmanaqes information by^eeejvm gand receives support for encrypting information 
th e support being prov i ded by from an encryption support system, comprising: 

a receiving portion feffeceivrngthat receives rule Information that indicates an encryption 
rule of information defined for each secret level that is a level of wanting to keep information 
secret and encryption data that are necessary for encrypting information in accordance with the 
rule from the encryption support system; 

a classification secret level storing portion fefsterin gthat stores classification of 
information managed by the information management system for each classification in 
connection with the secret level; 

an encrypting portion for encrypting that encrypts information managed by the information 
management system by using the encryption data of the secret level corresponding to the 
classification of the information received by the receiving portion; 

an information storing portion fe^sterin gthat stores the information encrypted by the 
encrypting portion; and 

a process information transmitting portion for tranomitting that transmits process 
information that indicates the encryption process performed by the encrypting portion to the 
encryption support system so as to receive a check whether or not the encryption of the 
information was performed in accordance with the rule. 

6. (CURRENTLY AMENDED) An encryption support system that encrypts 
information and sn ppnrH f n rT i ip po rt i ng ^n information management system for monagingthat 
mjnaaes information s e ncrypt informati on, the encryption support system comprising: 
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an encryption rule storing portion feHstefm gthat stores rule information that indicates an 
encryption rule of the information for each secret level that is a level of wanting to keep 
information secret; 

a transmitting portion for troncmitt i n g that transmits encryption data that is necessary for 
encrypting information in accordance with the rule to the information management system; 

a receiving portion fetweeeivwgthat receives process information that indicates the 
encryption process performed by the information management system from the information 
management system; 

a monitoring portion for monitoring that monitors whether or not the encryption of 
information is performed in accordance with the rule by the information management system on 
the basis of the process information received from the information management system; and 

a warning portion fer-wamiwgth at warns the information management system that was 
found to encrypt information not in accordance with the rule by the monitoring portion to do 
encryption of information in accordance with the rule. 

7. (CURRENTLY AMENDED) An encryption support system according to claim 6, 
further comprising a validity monitoring portion for monitoring that monitors validity of an 
encryption rule that is used currently in accordance with vulnerability information about 
vulnerability of security received from a security information providing portion, wherein 

the transmitting portion transmits the encryption data for changing the rule appropriately 
to the information management system if it is decided that the encryption rule that is used 
currently has little validity. 

8. (CURRENTLY AMENDED) A computer program product for use in a computer 
supporting encryption of information for an information management system that manages 
information, the computer program produc t causing the computer to execute a process 
comprising: 

meafls-feMransmitting rule information that indicates an encryption rule of the information 
for each secret level that is a level of wanting to keep information secret and encryption data that 
is necessary for encrypting information in accordance with the rule to the information 
management system; 

moons for r eceiving process information that indicates the encryption process performed 
by the information management system from the information management system; 
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m e ans, for monitoring whether or not the encryption of information is performed in 
accordance with the rule by the information management system on the basis of the process 
Information received from the information management system; and 

m e ans for - w arning the information management system that was found to encrypt 
information not in accordance with the rule by the monitoring means to do encryption of 
information in accordance with the rule. 

9. (NEW) A method, comprising: 

monitoring whether data is encrypted in accordance with a predetermined encryption rule 
for a security level; and 

producing a warning if the data is not encrypted in accordance with the encryption rule. 

10. (NEW) A method, comprising: 

monitoring whether an information management system encrypts data in accordance with 
an encryption rule associated with a security level of the information management system; and 

warning the information management system if the data is not encrypted in accordance 
with the encryption rule. 
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